Evidence-linked product lifecycle intelligenceSUPPORT · SECURITY · RETIREMENT
← Search results
CVE-LINKED INVENTORY144 SECURITY RECORDS

Apache Software Foundation

Apache Airflow

Affected and fixed version statements observed in the public BlackTree CVE catalogue. These statements describe vulnerability scope, not publisher support entitlement.

Lifecycle evidence status

This identity is present in BlackTree CVE records, but no product-specific publisher support or retirement history is currently registered in Lifecycle.

A missing support date does not mean the product is supported. CVE publication dates and affected-version ranges must not be interpreted as EOL dates.

CVE-observed version history

CVEPublishedAffected versionsFixed version informationPublisher evidence
CVE-2025-66236 13 Apr 2026 Apache Airflow: 3.0.0 < 3.2.0 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2025-57735 9 Apr 2026 Apache Airflow: 3.0.0 < 3.2.0 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-34538 9 Apr 2026 3.0.0 < 3.2.0 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-28563 17 Mar 2026 3.0.0 < 3.1.8 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-26929 17 Mar 2026 3.0.0 < 3.1.8 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-30911 17 Mar 2026 3.1.0 < 3.1.8 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-28779 17 Mar 2026 3.0.0 < 3.1.8 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2025-27555 24 Feb 2026 < 2.11.1 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2024-56373 24 Feb 2026 < 2.11.1 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2025-65995 21 Feb 2026 3.0.0 < 3.1.4; < 2.11.1 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-22922 9 Feb 2026 3.1.0 < 3.1.7 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-24098 9 Feb 2026 3.0.0 < 3.1.7 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2025-68675 16 Jan 2026 3.0.0 < 3.1.6; < 2.11.1 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2025-68438 16 Jan 2026 3.1.0 < 3.1.6 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2025-66388 15 Dec 2025 Apache Airflow: 3.1.0 < 3.1.4 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2025-54941 30 Oct 2025 3.0.0 < < 3.0.5 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2025-62402 30 Oct 2025 3.0.0 < 3.1.1 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2025-62503 30 Oct 2025 3.0.0 < 3.1.1 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2025-54831 26 Sep 2025 3.0.3 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2024-45784 15 Nov 2024 < 2.10.3 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2024-50378 8 Nov 2024 < 2.10.3 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2024-45034 7 Sep 2024 < 2.10.1 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2024-45498 7 Sep 2024 2.10.0 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2024-41937 21 Aug 2024 < 2.10.0 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2024-39877 17 Jul 2024 2.4.0 < 2.9.3 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2024-39863 17 Jul 2024 < 2.9.3 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2024-25142 14 Jun 2024 < 2.9.2 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2024-32077 14 May 2024 2.9.0 < 2.9.1 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2024-31869 18 Apr 2024 2.7.0 ≤ 2.8.4 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2024-29735 26 Mar 2024 2.8.2 ≤ 2.8.3 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2024-28746 14 Mar 2024 2.8.0 < 2.8.3 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2024-26280 1 Mar 2024 < 2.8.2 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2024-27906 29 Feb 2024 < 2.8.2 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2023-50944 24 Jan 2024 < 2.8.1 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2023-50943 24 Jan 2024 < 2.8.1 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2023-48291 21 Dec 2023 < 2.8.0 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2023-50783 21 Dec 2023 < 2.8.0 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2023-47265 21 Dec 2023 2.6.0 < 2.8.0 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2023-49920 21 Dec 2023 2.7.0 < 2.8.0 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2023-42781 12 Nov 2023 < 2.7.3 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2023-47037 12 Nov 2023 < 2.7.3 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2023-46288 23 Oct 2023 2.4.0 < 2.7.0 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2023-42663 14 Oct 2023 < 2.7.2 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2023-42792 14 Oct 2023 < 2.7.2 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2023-45348 14 Oct 2023 2.7.0 < 2.7.2 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2023-42780 14 Oct 2023 < 2.7.2 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2023-40712 12 Sep 2023 < 2.7.1 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2023-40611 12 Sep 2023 < 2.7.1 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2023-37379 23 Aug 2023 < 2.7.0 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2023-40273 23 Aug 2023 < 2.7.0 No fixed version is explicitly recorded in the structured CVE data. Use CVE record

How this record is maintained

The CVE inventory is reconciled automatically from cve.blacktree.nl. Exact identity matches link to existing Lifecycle product or package histories. Unmatched products stay in a prioritised publisher-source research queue, and Lifecycle marks the date gap instead of inferring a support boundary from vulnerability data.